Bug 55116 - Description of univention-run-join-scripts options -dcaccount and -dcpwd misleading
Description of univention-run-join-scripts options -dcaccount and -dcpwd misl...
Status: NEW
Product: UCS
Classification: Unclassified
Component: Join (univention-join)
UCS 5.0
Other Linux
: P5 normal (vote)
: ---
Assigned To: UCS maintainers
UCS maintainers
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-08-18 19:32 CEST by Arvid Requate
Modified: 2022-08-19 08:51 CEST (History)
1 user (show)

See Also:
What kind of report is it?: Development Internal
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): bitesize
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2022-08-18 19:32:41 CEST
The description of the -dcaccount and -dcpwd are misleading:
===========
Syntax:
  univention-run-join-scripts [options] [script, ...]

Options:
  -dcaccount <account>:    name of Primary Directory Node account
  -dcpwd <password file>:  file with Primary Directory Node password

===========

That should read "name of a member of the group `Domain Admins`". As it stands I read that as: Enter the name of the account of the Primary Directory Node.


Likewise it says interactively:
===========
root@replica:~# univention-run-join-scripts 
univention-run-join-scripts: runs all join scripts existing on local computer.
copyright (c) 2001-2022 Univention GmbH, Germany

Enter Primary Directory Node Account : Administrator
Enter Primary Directory Node Password:
===========
Comment 1 Erik Damrose univentionstaff 2022-08-19 08:51:43 CEST
> That should read "name of a member of the group `Domain Admins`"

Maybe we should phrase it more carefully ("Username of a user with join permissions"), or doublecheck what attributes / group memberships are required for a joinuser: I know that the account has to be in "DC Backup Hosts" to allow the download of the server ssl certificates.